Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?
Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?
When a mandatory security standard hinders the achievement of an identified business objective, the first step an information security manager should take is to escalate the issue to senior management. This allows senior management to evaluate the situation at a higher level, consider the potential risks, and make an informed decision. Senior management has the authority to weigh the business impact and make decisions regarding adjustments to the business objective, resource allocation, or seeking exceptions to the security standard.
at first, perform ROI.
Before approaching the SM, the infosec manager should do his homework (cost of non-compliance vs benefits of compliance)
Very much B in this case
C. Escalate to senior management. Escalating the issue to senior management allows for a higher-level decision-making process. Senior management can evaluate the situation, consider the potential risks, and make an informed decision regarding whether to adjust the business objective, allocate additional resources, seek exceptions or waivers from the security standard, or take other appropriate actions. After senior management is aware of the issue and involved in the decision-making process, they may then decide to perform a cost-benefit analysis, revisit the business objective, or recommend risk acceptance if necessary.
C. Escalate to senior management.
When a mandatory security standard hinders the achievement of an identified business objective, the information security manager should first perform a cost-benefit analysis to determine the impact of the security standard on the business objective.
C first
Escalate to senior management.
C. Escalate to senior management.
Escalate based on the scenario - mandatory control, and the bottle kneck to objectives. You would have done the cost benefit-analysis prior to selecting the mandatory requirements. C
Why would he bother with B when the hindrance is being caused by a mandated control? The question implies that the control must remain in place so how or why would you need to weigh it up?
B. Perform a cost-benefit analysis.